CVE-2026-90199

Published: Set 17, 2026 Last Modified: Set 18, 2026
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 7,8
Source: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Attack Vector: local
Attack Complexity: low
Privileges Required: none
User Interaction: required
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: high

Description

AI Translation Available

In the Linux kernel, the following vulnerability has been resolved:

fs/ntfs3: reject out-of-range evcn in mi_enum_attr()

In mi_enum_attr(), the start/end VCN validation for non-resident
attributes is:

if (svcn > evcn + 1) goto out;

When evcn is U64_MAX the 'evcn + 1' expression wraps to 0 and any svcn
passes the check. For evcn values close to U64_MAX (but not equal to it)
the right-hand side is still a meaningless near-wrap upper bound, so a
malformed on-disk attribute with svcn == 0 and evcn near U64_MAX can pass
mi_enum_attr() unrejected.

VCN (virtual cluster number) is a cluster index, so any valid evcn is
bounded by the volume's total cluster count, which ntfs3 holds in
sbi->used.bitmap.nbits (set up in ntfs_init_from_boot() before any caller
of mi_enum_attr() runs). Reject evcn values that fall outside this range.

However, an empty non-resident attribute (no allocated clusters) is
legitimately encoded with svcn == 0 and evcn == -1 (U64_MAX), e.g. via
attr->nres.evcn = cpu_to_le64((u64)vcn - 1) with vcn == 0. That sentinel
must keep passing, so exclude evcn == U64_MAX from the range check. The
existing 'svcn > evcn + 1' test still tolerates the sentinel ('0 > 0' is
false) and continues to require svcn == 0 for it, while the range check
rejects every other out-of-range evcn and thereby also defuses the
'evcn + 1' wraparound.

svcn does not need its own bound: once evcn < nbits, 'svcn > evcn + 1'
implies svcn <= nbits.

[[email protected]: fixed evcn check]

https://git.kernel.org/stable/c/0441e34ce098c19185a7b52c5b8b89a8a5b26888
https://git.kernel.org/stable/c/20fd9f64c0050658f2031e6bd5d552c6f0c8f7e3
https://git.kernel.org/stable/c/2b9a0e57bfd365e2096706b19ae34dce3b4a884b
https://git.kernel.org/stable/c/7ab69cef49ebdfee288287d62641b24ab1445ecc
https://git.kernel.org/stable/c/ce9a619c432b9a4044fee115c5483fbed946c131